Hi guys,
currently we have two locations with two CheckPoint lcuster on each side. There is MPLS between them and we would like to create a route based VPN as a backup to the MPLS.
So far we have configured empty VPN domains, gateways (cluster) objects on each side, VPN community on each side, we created virtual tunnel interfaces for each gw and for clusters. We set priority for MPLS 1 and priority for VTI tunnel as 8.
after we installed the policy on remote site, checkPoint started IKE communication and started putting all communication into the non existing route based VPN tunnel.
The question is, why did CheckPoint started sending all traffic to the non existing VPN tunnel even though VTI had lowest route priority possible.
We reverted changes and everything is working now.